Impact
Concrete CMS versions below 9.5.3 are vulnerable to PHP Object Injection because the Workflow, Form block, and File/Set components use unserialize() without restricting allowed_classes. The Form block and File/Set sinks were patched in 9.5.2, and the Workflow component was fixed in 9.5.3. An unauthenticated attacker can trigger arbitrary PHP object instantiation by placing a malicious serialized payload in the CMS database; the flaw, identified as CWE‑502, enables code execution with the privileges of the web application, potentially compromising confidentiality, integrity, and availability of the host system. The CVSS v4.0 score of 8.4 indicates a high‑severity condition with low effort and local access required.
Affected Systems
Concrete CMS installations running any version prior to 9.5.3 are susceptible. The Form block and File/Set components were corrected in 9.5.2, while the Workflow component was addressed in 9.5.3. Users on earlier releases, or on 9.5.2 with active workflows, must verify their version and apply an upgrade.
Risk and Exploitability
The CVSS score of 8.4 highlights a high‑severity condition with low effort to exploit (local access required, low attack complexity, no authentication needed). Based on the description, the likely attack vector requires an attacker to place a crafted payload in the CMS database, thus triggering the vulnerable unserialize() calls that lead to arbitrary PHP object instantiation. The EPSS score of less than 1 % indicates that active exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog, so there are no documented public exploits. Nevertheless, the impact of successful exploitation is the potential for complete code execution on the system.
OpenCVE Enrichment
Github GHSA